PT-2026-51446 · Unknown · Openkm Community Edition

CVE-2026-46495

·

Published

2026-06-22

·

Updated

2026-06-25

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenDJ Community Edition versions prior to 5.1.1
Description A Deserialization of Untrusted Data issue in the JMX RMI connector allows an unauthenticated remote attacker to deserialize arbitrary Java objects on the server. The issue occurs because the platform processes attacker-controlled bytes before authentication. This affects systems where the JMX Connection Handler is enabled, which is often done for monitoring integrations. Successful exploitation leads to Remote Code Execution (RCE), the severity of which depends on the Java version and runtime classpath.
Recommendations Update to version 5.1.1. As a temporary mitigation, disable the JMX Connection Handler if it is not required for monitoring.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46495
GHSA-43X2-G84Q-FMQX

Affected Products

Openkm Community Edition